2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7581CRITICAL9.8A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasic...
CVE-2024-7580CRITICAL9.8A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by thi...
CVE-2024-42005HIGH7.3An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on...
CVE-2024-41991HIGH7.5An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, a...
CVE-2024-41990HIGH7.5An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filter...
CVE-2024-41989HIGH7.5An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to ...
CVE-2024-7579HIGH8.8A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by ...
CVE-2024-43199HIGH7.8Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned ...
CVE-2024-43045MEDIUM6.3Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing att...
CVE-2024-43044HIGH8.8Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins contr...
CVE-2024-7578CRITICAL9.8A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected i...
CVE-2024-7355MEDIUM5.4The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node...
CVE-2024-7353MEDIUM5.4The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_str...
CVE-2024-7267MEDIUM6.5Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy E...
CVE-2024-7266MEDIUM4.3Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al...
CVE-2024-7265HIGH8.8Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP al...
CVE-2024-6522CRITICAL9.6The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ...
CVE-2024-7553HIGH7.8Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underl...
CVE-2024-5290HIGH7.8An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a lo...
CVE-2024-42222MEDIUM4.3In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network detail...
CVE-2024-42062HIGH7.2CloudStack account-users by default use username and password based authentication for API and UI access. Account-users ...
CVE-2024-6494MEDIUM6.1The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which...
CVE-2024-3973MEDIUM4.8The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-37403MEDIUM5.5Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to pr...
CVE-2024-36132HIGH7.5Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authen...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now